J2Commerce Professional v4
Description
Free without priority support
Specifications
- Developer J2Store/J2Commerce
Change Log
Fix Fix user delegated tasks fail unauthorized
Fix Cannot remove order items in the cart
Fix Force reload to avoid invalid token on registration
Fix Fix token handling in cart item removal link for mod_j2store_cart
Fix Fix typos in installer script
Improvement Improved CSRF token handling for new module files and update warnings in help.php and the installer script
New Feature Add error handling and logging for defaultPosition and withinArticle methods in j2store content plugin
Fix Fix user delegated tasks fail unauthorized
Fix Cannot remove order items in the cart
Fix Force reload to avoid invalid token on registration
Fix Fix token handling in cart item removal link for mod_j2store_cart
Fix Fix typos in installer script
Improvement Improved CSRF token handling for new module files and update warnings in help.php and the installer script
Fix CVE-2026-78081 Missing CSRF protection on cart, checkout and myprofile controllers
Fix CVE-2026-81567 Blind SQL injection in the storefront product list
Fix CVE-2026-81568 Arbitrary file read via `task=download`
Fix CVE-2026-82189 Any order can be marked Failed by anyone
Fix CVE-2026-82190 Predictable/forgeable order access token
Fix CVE-2026-82191 Unescaped request data reflected into PayPal notify redirect
Fix CVE-2026-78081 Missing CSRF protection on cart, checkout and myprofile controllers
Fix CVE-2026-81567 Blind SQL injection in the storefront product list
Fix CVE-2026-81568 Arbitrary file read via `task=download`
Fix CVE-2026-82189 Any order can be marked Failed by anyone
Fix CVE-2026-82190 Predictable/forgeable order access token
Fix CVE-2026-82191 Unescaped request data reflected into PayPal notify redirect
Fix CVE-2026-77999 Unauthenticated PayPal callback forgery
Fix CVE-2026-78000 Reflected XSS via filter_tag, pricefrom and priceto
Fix CVE-2026-78064 Anonymous cart-record tampering through inherited FOF tasks
Fix CVE-2026-78065 Guest address readable by any registered user
Fix CVE-2026-78069 Apps delegation chain currently shielded by accident
Fix CVE-2026-77999 Unauthenticated PayPal callback forgery
Fix CVE-2026-78000 Reflected XSS via filter_tag, pricefrom and priceto
Fix CVE-2026-78064 Anonymous cart-record tampering through inherited FOF tasks
Fix CVE-2026-78065 Guest address readable by any registered user
Fix CVE-2026-78069 Apps delegation chain currently shielded by accident
Fix CVE-2026-67358 - Quota manipulation
Fix CVE-2026-67359 - Order content disclosure
Fix CVE-2026-67360 - Cross-customer order replication
Fix CVE-2026-67361 - File Upload
Fix CVE-2026-67362 - Open Redirect
Fix CVE-2026-74252 - Guest checkout cookie bypass
Fix
Fix CVE-2026-67358 - Quota manipulation
Fix CVE-2026-67359 - Order content disclosure
Fix CVE-2026-67360 - Cross-customer order replication
Fix CVE-2026-67361 - File Upload
Fix CVE-2026-67362 - Open Redirect
Fix CVE-2026-74252 - Guest checkout cookie bypass
Fix
Fix Cast as char database calls in search plugin
Fix PayPal custom field creates an error
Fix Issues adding images on the product page
Fix Double escaping of tags in the checkout fields
Improvement Modified the FOF message when FOF libraries must be cleaned up on install
Improvement Updated the code with safe DOM methods, escaped variables
Fix Installer plugin loads the wrong URI library
Documentation
Go PRO. Get More Features.
Discount Coupons, Vouchers
Attract more customers and encourage them to buy more with discount coupons, vouchers and more.
Manage Stock Easily
Manage your inventory efficiently with J2Commerce. Do not oversell. Your store can auto-deduct the stock once the customer places a successful order.
Add more tools to your store
Create and send professionally designed emails and invoices to your customers. Add quantity restrictions and much, much more.
What's Changed
- 4.1.5 - Miscellaneous fixes by @j2commerce in https://github.com/j2commerce/j2cart/pull/299
FIXED Cast as char database calls in search plugin
FIXED PayPal custom field creates an error
FIXED issues adding images on the product page
FIXED double escaping of tags in the checkout fields
MODIFIED the FOF message when FOF libraries must be cleaned up on install
UPDATED the code with safe DOM methods, escaped variables
- *Full Changelog**: https://github.com/j2commerce/j2cart/compare/v4.1.4...v4.1.5
Stay Updated
Subscribe for free and be the first to know about the latest features, updates, and new additions.